Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Anthropic’s Claude AI can respond with charts, diagrams, and other visuals now

    Anthropic’s Claude AI can respond with charts, diagrams, and other visuals now

    March 12, 2026
    Gemini’s task automation is here and it’s wild

    Gemini’s task automation is here and it’s wild

    March 12, 2026
    Google Chrome is coming to Arm-powered Linux devices later this year

    Google Chrome is coming to Arm-powered Linux devices later this year

    March 12, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Researchers say a bug let them add fake pilots to rosters used for TSA checks
    News

    Researchers say a bug let them add fake pilots to rosters used for TSA checks

    News RoomBy News RoomSeptember 8, 20242 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Researchers say a bug let them add fake pilots to rosters used for TSA checks

    A pair of security researchers say they discovered a vulnerability in login systems for records that the Transportation Security Administration (TSA) uses to verify airline crew members at airport security checkpoints. The bug let anyone with a “basic knowledge of SQL injection” add themselves to airline rosters, potentially letting them breeze through security and into the cockpit of a commercial airplane, researcher Ian Carroll wrote in a blog post in August.

    Carroll and his partner, Sam Curry, apparently discovered the vulnerability while probing the third-party website of a vendor called FlyCASS that provides smaller airlines access to the TSA’s Known Crewmember (KCM) system and Cockpit Access Security System (CASS). They found that when they put a simple apostrophe into the username field, they got a MySQL error.

    This was a very bad sign, as it seemed the username was directly interpolated into the login SQL query. Sure enough, we had discovered SQL injection and were able to use sqlmap to confirm the issue. Using the username of ‘ or ‘1’=’1 and password of ‘) OR MD5(‘1’)=MD5(‘1, we were able to login to FlyCASS as an administrator of Air Transport International!

    Once they were in, Carroll writes that there was “no further check or authentication” preventing them from adding crew records and photos for any airline that uses FlyCASS. Anyone who might have used the vulnerability could present a fake employee number to get through a KCM security checkpoint, the blog says.

    TSA press secretary R. Carter Langston denied that, telling Bleeping Computer that the agency “does not solely rely on this database to authenticate flight crew, and that “only verified crewmembers are permitted access to the secure area in airports.”

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleElectric Grilling Is Still a Little Raw in the Middle
    Next Article These new Aukey wireless chargers come with cooling fans

    Related Posts

    Anthropic’s Claude AI can respond with charts, diagrams, and other visuals now

    Anthropic’s Claude AI can respond with charts, diagrams, and other visuals now

    March 12, 2026
    Gemini’s task automation is here and it’s wild

    Gemini’s task automation is here and it’s wild

    March 12, 2026
    Google Chrome is coming to Arm-powered Linux devices later this year

    Google Chrome is coming to Arm-powered Linux devices later this year

    March 12, 2026
    KPop Demon Hunters is getting a sequel, obviously

    KPop Demon Hunters is getting a sequel, obviously

    March 12, 2026
    The original AirTag is the cheapest it’s ever been

    The original AirTag is the cheapest it’s ever been

    March 12, 2026
    What it was like to watch grieving parents stare down Mark Zuckerberg in court

    What it was like to watch grieving parents stare down Mark Zuckerberg in court

    March 12, 2026
    Our Picks
    Gemini’s task automation is here and it’s wild

    Gemini’s task automation is here and it’s wild

    March 12, 2026
    Google Chrome is coming to Arm-powered Linux devices later this year

    Google Chrome is coming to Arm-powered Linux devices later this year

    March 12, 2026
    KPop Demon Hunters is getting a sequel, obviously

    KPop Demon Hunters is getting a sequel, obviously

    March 12, 2026
    The original AirTag is the cheapest it’s ever been

    The original AirTag is the cheapest it’s ever been

    March 12, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    What it was like to watch grieving parents stare down Mark Zuckerberg in court News

    What it was like to watch grieving parents stare down Mark Zuckerberg in court

    By News RoomMarch 12, 2026

    Around a dozen parents huddled in the dim hallway outside the courtroom in February, nervously…

    Facebook Marketplace adds AI auto-replies for annoying ‘Is this still available?’ messages

    Facebook Marketplace adds AI auto-replies for annoying ‘Is this still available?’ messages

    March 12, 2026
    Google’s TV Streamer 4K doubles as a smart home hub and it’s on sale

    Google’s TV Streamer 4K doubles as a smart home hub and it’s on sale

    March 12, 2026
    Meta exec hopes VR teens will stick around

    Meta exec hopes VR teens will stick around

    March 12, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.